MuonTrap: Preventing Cross-Domain Spectre-Like Attacks by Capturing Speculative State

MuonTrap: Preventing Cross-Domain Spectre-Like Attacks by Capturing Speculative State
复制标题

DOI:
10.1109/isca45697.2020.00022
复制
发表时间:
2019-11
期刊:
2020 ACM/IEEE 47th Annual International Symposium on Computer Architecture (ISCA)
影响因子:
--
通讯作者:
S. Ainsworth;Timothy M. Jones
S. Ainsworth;Timothy M. Jones
中科院分区:
其他
文献类型:
--
作者:
S. Ainsworth;Timothy M. Jones

文献摘要

被引文献

相似文献

2018年1月Spectre投机执行攻击的披露留下了一个严重的漏洞,系统仍在努力寻找如何修补。目前存在的解决方案往往具有不完整的覆盖,性能很差,或者具有非常不理想的性能边缘情况。MuonTrap允许处理器继续推测,在不影响安全性的情况下避免显著降低性能。相反,我们通过将推测缓存访问的结果放置到一个小而快速的L0过滤器缓存中,从而防止基于推测执行的任何状态的传播,该缓存与缓存层次结构的其余部分不包含、不排斥。这隔离了系统中不能在威胁域发生任何变化时快速清除的所有部分。MuonTrap使用这些推测过滤器缓存,它们在上下文和保护域开关上被清除,以及对缓存一致性协议和预取器的一系列扩展。这使得系统不受Spectre跨域信息泄露和基于推测执行的一系列类似攻击的影响,性能影响低,对CPU设计的更改很少。
The disclosure of the Spectre speculative-execution attacks in January 2018 has left a severe vulnerability that systems are still struggling with how to patch. The solutions that currently exist tend to have incomplete coverage, perform badly, or have highly undesirable performance edge cases.MuonTrap allows processors to continue to speculate, avoiding significant reductions in performance, without impacting security. We instead prevent the propagation of any state based on speculative execution, by placing the results of speculative cache accesses into a small, fast L0 filter cache, that is non-inclusive, non-exclusive with the rest of the cache hierarchy. This isolates all parts of the system that can’t be quickly cleared on any change in threat domain. MuonTrap uses these speculative filter caches, which are cleared on context and protection-domain switches, along with a series of extensions to the cache coherence protocol and prefetcher. This renders systems immune to cross-domain information leakage via Spectre and a host of similar attacks based on speculative execution, with low performance impact and few changes to the CPU design.